
Kelp DAO says a single-validator LayerZero setup helped enable the rsETH bridge hack, adding a new technical dispute over responsibility after the reported April 18 theft.
Kelp DAO has disputed LayerZero’s official explanation of the reported rsETH bridge exploit, saying a LayerZero “default” single-validator setup helped enable the attack and triggered a rushed security migration after roughly $290 million was stolen. This adds a new technical disagreement to earlier statements that tied the incident to compromised RPC infrastructure and said the issue was limited to KelpDAO’s rsETH configuration. The exploit was previously reported as involving about 116,500 rsETH worth roughly $291 million to $293 million, with affected protocols including Aave and Lido taking containment measures such as market freezes and deposit or withdrawal pauses.